Conditional Access policy removed
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AzureAD Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Modify Authentication Process: Conditional Access Policies (T1556.009)
Severity
Low
Description
An identity removed a Conditional Access policy.
Attacker's Goals
An attacker attempts to change Active Directory configuration for persistence or defense evasion.
Without a Conditional Access policy, an attacker would be able to access the tenant without possible blockage for later access.
Investigative actions
Check implications of the policy being removed.
Check whether the user changing the configuration is permitted to perform such actions.
Was this helpful?
